DORA Governance and Penalties

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

DORA governance combines national competent authority supervision, ESA cross-sector coordination, and Joint Oversight Mechanism for CTPPs. Penalties set by Member States; supervisory powers include withdrawal of authorization for severe non-compliance.

National competent authorities

Member States designate competent authorities per financial sector:

  • Banking: typically banking supervisor (DE: BaFin; FR: ACPR; IT: Banca d'Italia).
  • Securities: securities authority (DE: BaFin; FR: AMF; IT: CONSOB).
  • Insurance: insurance supervisor (DE: BaFin; FR: ACPR; IT: IVASS).
  • Other sectors: per Member State structure.

National competent authorities exercise day-to-day supervision over financial entities. Coordinated with ESAs for cross-cutting issues.

ESAs (Joint Committee for DORA)

EBA, ESMA, EIOPA cooperate via Joint Committee on DORA matters. Tasks:

  • Develop RTS / ITS jointly.
  • Designate CTPPs.
  • Coordinate Lead Overseer assignments.
  • Issue cross-sector guidelines.
  • Cooperate with ENISA and Cooperation Group on NIS2 interactions.

Joint Oversight Mechanism for CTPPs

Lead Overseer

For each CTPP, one ESA designated as Lead Overseer based on:

  • Sector concentration in CTPP's financial-entity customer base.
  • ESA expertise.
  • ESA discretion.

Lead Overseer:

  • Conducts ongoing oversight of CTPP.
  • Issues recommendations.
  • Cooperates with other ESAs via Joint Oversight Network.
  • Can impose periodic penalty payments.

Joint Oversight Network

ESAs + Member State competent authorities collaborating on CTPP oversight:

  • Joint examinations.
  • Information sharing.
  • Coordinated supervisory actions.

Powers (Articles 35-39)

Lead Overseer can:

  • Request information from CTPP.
  • Conduct general investigations.
  • Conduct on-site inspections at CTPP premises.
  • Issue recommendations.
  • Impose periodic penalty payments (Article 35(6)) — up to 1% of average daily worldwide turnover of preceding business year, per day of non-compliance, for up to six months.

CTPP non-cooperation can trigger recommendation that financial entities terminate or modify CTPP relationships — commercial pressure on CTPP.

Supervision of financial entities (Articles 50-56)

National competent authorities supervise financial entities' DORA compliance:

  • Information requests (Article 50).
  • General investigations (Article 51).
  • On-site inspections (Article 52).
  • Pre-emptive measures (Article 53) — to prevent imminent serious damage.
  • Corrective measures (Article 54) — orders, restrictions.
  • Withdrawal of authorization (Article 56) for severe non-compliance.

Supervision is risk-based and proportional.

Penalties

DORA does not set EU-wide penalty caps. Member States establish penalties per national law (Article 50(5)).

Penalties must be:

  • Effective
  • Proportionate
  • Dissuasive

Member State implementations vary. Typical penalty types:

  • Administrative fines — varies by Member State, sector-specific limits.
  • Withdrawal of authorization — for severe / repeated violations.
  • Public statements identifying violations.
  • Cease-and-desist orders.
  • Periodic penalty payments.
  • Personal liability of management body members (some Member States).

DE BaFin penalties under DORA — administered through existing BaFin enforcement framework (KWG, ZAG, VAG, WpHG depending on sector).

CTPP periodic penalty payments

Lead Overseer can impose periodic penalty payments on CTPPs:

  • Daily fines.
  • Up to 1% of average daily worldwide turnover (preceding business year).
  • For up to six months.

This is the EU-level enforcement tool against non-cooperative CTPPs. Practical impact significant given large cloud / SaaS provider revenue.

Management body responsibility

Article 5 requires management body responsibility for ICT risk management framework. Combined with Member State personal liability provisions, management body members face real exposure.

Cooperation with other regimes

DORA authorities cooperate with:

  • GDPR DPAs for personal data breach overlap.
  • NIS2 authorities for non-financial cybersecurity overlap.
  • AI Act AI Office for AI feature obligations.
  • Member State criminal prosecutors where criminal aspects arise.
  • Other Member State authorities for cross-border matters.

Coordination guidance still maturing; first year of enforcement shaping practice.

SRE and AI-agent fit notes

Management body training in financial-AI context

Financial-entity management body training under DORA should include:

  • AI feature dependencies (foundation models, vendor concentration)
  • AI-specific threat awareness
  • AI-related TPP risks
  • AI-system incident response

CTPP designation implications for AI vendors

If Anthropic, OpenAI, Google, or other AI providers reach CTPP designation thresholds:

  • Lead Overseer oversight added.
  • Commercial terms with financial customers may shift.
  • Audit cooperation obligations on the AI vendor.
  • Potential for periodic penalty payments if non-cooperative.

Stefan-context implementation sketch

  • For financial-services engagements: support client governance maturation under DORA.
  • For potential CTPP-status AI vendors: anticipate evolving commercial landscape.

See also